Not enabled
Two-factor authentication
Time-based one-time codes required for login, withdrawal and API key creation.
Account
Security controls are enforced server-side. Each control below activates only after authentication is connected.
Time-based one-time codes required for login, withdrawal and API key creation.
Restrict withdrawals to pre-approved addresses with a mandatory cooling period.
A personal code included in every platform email so spoofed mail is obvious.
Require confirmation from a trusted device when signing in from a new location.
No session data
Device, IP, location and last-seen time are listed per session with remote sign-out.
No events
Password changes, 2FA updates and withdrawal approvals are logged immutably.